CVE-2026-75754
Received Received - Intake

Authentication Bypass and SSRF in ASUS Control Center

Vulnerability report for CVE-2026-75754, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: ASUS

Description

Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encryption key via an HTTP request, causing a local service to enable SSH on port 2222. The attacker can then log in with the hardcode credentials to obtain a root shell, enabling direct reading, writing, and deletion of data on ASUS Control Center, as well as remote control of all servers, PCs, and workstations within the company. Refer to the 'Security Update for ASUS Control Center' section on the ASUS Security Advisory for more information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-04
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
asus control_center *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves three critical issues in ASUS Control Center: missing authentication for critical functions, server-side request forgery (SSRF), and use of hard-coded credentials. An unauthorized user can exploit these flaws to obtain encryption keys via HTTP requests, enabling SSH on port 2222 with hardcoded credentials. This grants root access, allowing full control over data and systems managed by ASUS Control Center.

Impact Analysis

This vulnerability allows attackers to gain root-level access to ASUS Control Center, enabling them to read, write, or delete sensitive data, and remotely control all connected servers, PCs, and workstations. This could lead to data breaches, unauthorized system modifications, or complete takeover of infrastructure.

Compliance Impact

This vulnerability likely violates compliance requirements under GDPR and HIPAA due to unauthorized access to sensitive data and potential data breaches. Organizations using ASUS Control Center may face legal penalties, loss of certification, and reputational damage for failing to protect personal or health information.

Mitigation Strategies

Apply the security update for ASUS Control Center as referenced in the ASUS Security Advisory to address missing authentication, SSRF, and hard-coded credentials issues.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75754. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart